Express Computer
Home  »  News  »  Data shows the “Vulnpocalypse” is a myth — Only 1.5% of CVEs ever get exploited

Data shows the “Vulnpocalypse” is a myth — Only 1.5% of CVEs ever get exploited

0 9

Security teams have long operated under a simple, anxiety-inducing assumption: every new CVE is a new fire to put out. A new report from vulnerability-management startup Root Evidence argues that assumption is wrong — and that the data has said so for years.

The company’s newly released “Vulnpocalypse Report” analyzed 253,912 CVEs published between January 2018 and mid-July 2026, cross-referencing them against confirmed exploitation data from CISA’s Known Exploited Vulnerabilities (KEV) catalog and VulnCheck KEV. The result: just 3,769 vulnerabilities — roughly 1.48% of the total — have ever been confirmed as exploited in the wild. The other 98.5% have not shown up in a real-world attack in the dataset Root Evidence examined.

That ratio has held remarkably steady. In every complete year from 2018 through 2025, the share of newly disclosed CVEs with confirmed exploitation stayed under 2.2% — even as the annual volume of published CVEs grew roughly two-and-a-half times over.

AI Hasn’t Changed the Math — Yet

One of the report’s more pointed findings pushes back on a narrative that’s gained traction across the security industry: that generative AI is accelerating the pace and volume of real-world exploitation. Root Evidence’s researchers found record numbers of CVEs being published, but no matching uptick in exploitation rates or in the proportion of bugs hit as true zero-days. The report stops short of drawing a causal line between AI tooling and the rise in CVE publication, but it found nothing in the exploitation data to support claims of a broad, AI-driven acceleration in attacks.

Key Findings
Most vulnerabilities are never weaponized. Only 3,769 of 253,912 CVEs since 2018 have confirmed exploitation.

Patches usually come first. 81.1% of exploited CVEs — 3,058 of 3,769 — were “n-days,” exploited only after a patch was already available. Just 711 were true zero-days.

Defenders generally have time. The median gap between patch release and first confirmed exploitation hit 116 days in 2026 through mid-July. Still, 33.5% of this year’s n-days were exploited within 30 days of patching, while 30.4% weren’t touched until more than a year later.

The same targets, year after year. Microsoft has topped the n-day exploitation count for nine consecutive years, and OS command injection, path traversal, and SQL injection have remained fixtures among the most-exploited vulnerability classes since 2018.

The Takeaway for Prioritization

For an industry that has spent years scaling patch-management programs around raw CVE counts, the report’s core argument is a reframe of where the real risk sits. As Root Evidence CEO Jeremiah Grossman put it, “Security teams have spent years counting vulnerabilities.” The report’s broader point is that exploitation data — not disclosure volume — is what should be driving remediation priorities, since it identifies a far smaller, more targetable population of vulnerabilities than the full CVE catalog suggests.

Grossman expanded on the findings in a companion blog post, “The Lion Isn’t Always in the Bushes,” published alongside the report on Root Evidence’s site. The full “Vulnpocalypse Report” is available for download directly from Root Evidence.

Leave A Reply

Your email address will not be published.